CRX aminer
Extension icon

Telegram Blur - Advanced Telegram Web Privacy

Version 3.1.0 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Rating: 4.8 ★ (13 ratings)
Users: 10,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a solid 4.8-star rating from 13 reviews and serves 10,000 users, suggesting legitimate functionality. The specific focus on Telegram Web privacy appears to align with user needs for enhanced privacy controls. However, the limited review count and missing developer information reduce overall trustworthiness.

Concerns:

The most significant concern is the broad content script injection capability across all URLs (<all_urls>), which far exceeds what's necessary for a Telegram-specific privacy tool. This permission allows the extension to access and modify content on every website you visit, creating substantial privacy and security risks. While the extension legitimately needs access to web.telegram.org, the universal access is excessive and potentially dangerous. The storage permission, while concerning, is relatively standard for extensions that need to save user preferences.

Recommendations:

Given the high-risk broad injection capability, consider running this extension in a separate Chrome profile dedicated to Telegram use only. This isolates potential risks from your main browsing activities. Alternatively, look for similar privacy extensions that request more limited permissions specific to Telegram domains. If you choose to keep it, regularly monitor your browser for unusual behavior and consider disabling it when not actively using Telegram Web. The functionality may be legitimate, but the excessive permissions create unnecessary attack surface.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.